curl --request GET \
--url https://api.gigstack.io/v2/retentions/{id}/files \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/retentions/{id}/files', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/retentions/{id}/files"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": [
{
"content": "JVBERi0xLjcKJeLjz9MKMSAwIG9iago8PC9UeXBlIC9DYXRhbG9nPj4K...",
"filename": "7F3A1C2E-4B5D-4E6F-8A9B-0C1D2E3F4A5B.pdf",
"type": "application/pdf"
}
],
"message": "Files retrieved successfully",
"timestamp": 1767225600000
}Get retention files
Retrieve PDF and/or XML files for a stamped tax retention document.
Use file_type query parameter to request specific file types.
gigstack Connect: Access other teams’ retention files using the team parameter.
curl --request GET \
--url https://api.gigstack.io/v2/retentions/{id}/files \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/retentions/{id}/files', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/retentions/{id}/files"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": [
{
"content": "JVBERi0xLjcKJeLjz9MKMSAwIG9iago8PC9UeXBlIC9DYXRhbG9nPj4K...",
"filename": "7F3A1C2E-4B5D-4E6F-8A9B-0C1D2E3F4A5B.pdf",
"type": "application/pdf"
}
],
"message": "Files retrieved successfully",
"timestamp": 1767225600000
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Path Parameters
Retention UUID
Query Parameters
Filter by file type. If omitted, returns both PDF and XML.
pdf, xml gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789